Permissions and Users
The Unix permission model: rwx bits and their octal shorthand, setuid/setgid/sticky, ACLs, the account files behind users and groups, and sudoers. Expect to be asked what 4755 means and why a setuid binary deserves suspicion.
part ofLinux & distributionsoverview, primer and where to startread it →on this pageshowhide
explore
- Mode bits, ownership and umask6 questions
- setuid, setgid and the sticky bit5 questions
- POSIX ACLs5 questions
- Linux capabilities5 questions
- Users, groups and sudo6 questions
- SELinux and AppArmor6 questions
- Linuxskillanchors this topic
- Backend Developerrole
- Blockchain Developerrole
- Cyber Security Expertrole
- Data Engineerrole
- DevOps / SRE Engineerrole
- DevSecOps Engineerrole
- Forward Deployed Engineerrole
- Full Stack Developerrole
- Java Backend Developerrole
- Java SDETrole
- Kotlin Backend Developerrole
- MLOps Engineerrole
- Network Engineerrole
- PostgreSQL DBArole
- QA Engineerrole
- Shell & Bashskill
questions
page 2 of 2A Linux user types the correct password and is still refused at login, with no message about a wrong password. Explain how PAM structures the login path and which stage rejects an otherwise-valid password.
basics
~20 sPAM splits authentication into four independent stacks: auth (are you who you say), account (are you allowed right now), password (changing the secret) and session (setting the session up). A correct password that still fails is almost always rejected by the account or session stack.
You set the access-control conventions for a fleet of Linux servers. When do you accept POSIX ACLs on shared directories, and when do you insist the access be expressed as group membership instead?
basics
~20 sUse group membership as the default, because it is managed centrally and audited in one place; use ACLs for genuine per-path exceptions that would otherwise force a single-purpose group. Any ACL you accept should be declared in configuration management, not applied by hand.
Your platform standard requires every Linux service to run under a non-root account with a minimal capability set. What does that requirement actually buy you, where does the capability model stop being a real boundary, and how do you decide when a workload needs something stronger?
basics
~20 sDropping to a minimal capability set removes specific kernel privileges and shrinks what a compromised process can escalate to. It is not a containment boundary: it does not restrict ordinary file access, syscall surface or network reach, and one root-equivalent capability undoes the whole set.
showing 31–33 of 33